Domain connection failure

Posted on 2013-01-30
Last Modified: 2013-08-06
following advise of today after a major power failure in the office.  Win7 clients stopped being able to connect to NAS drive and folder shares.  Suggestion was to reconnect the clients to the domain.  Have tried one client and it fails on the Network stage.  One trying from the Control panel this error is reported.  Anyone know of a solution?


The following error occurred when DNS was queried for the service location (SRV) resource record used to locate an Active Directory Domain Controller (AD DC) for domain "cs.loca":

The error was: "DNS name does not exist."
(error code 0x0000232B RCODE_NAME_ERROR)

The query was for the SRV record for _ldap._tcp.dc._msdcs.cs.loca

Common causes of this error include the following:

- The DNS SRV records required to locate a AD DC for the domain are not registered in DNS. These records are registered with a DNS server automatically when a AD DC is added to a domain. They are updated by the AD DC at set intervals. This computer is configured to use DNS servers with the following IP addresses:
Question by:TMS
  • 9
LVL 18

Expert Comment

ID: 38837333
Please check you DNS settings and make sure below best practices are correctly defined in your env

Best practices for DNS client settings on DC and domain members.

Author Comment

ID: 38837458
Sarang, The DNS looks fine.  I have noticed another issue after restarting the server and that is the RPC shows running in services but if I open Active Directory it say it is not and I can't open Active directory.  Outlook clients can't connect to exchange but my iphone does.
Seems something a little more fundimental is wrong.

Author Comment

ID: 38837477
One other thing.  I noticed that when using my account to log into one client it denied me with the trust error on the domain. When I used another admin account it logged in.  I'm wondering if some credentials have been corrupted?
LVL 70

Expert Comment

ID: 38837478
stop and restart the NETLOGON service, then check to see if the SRV records have been created.

Author Comment

ID: 38837526
Are you saying svr records will be created by the netlogon service?  It's restarting now.  It didn't let me the first time but second try and it is stopping and starting all the other services.
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.


Author Comment

ID: 38837534
Ok, all the svr records in DNS were time stamped an hour ago, probably when I restarted the server before

Author Comment

ID: 38837552
I have also noticed there are "?" Next to default domain and share point web services.  The sbs company web doesn't work and when I try to log onto the server via Remote Desktop or owa I get a certificate warning.

Author Comment

ID: 38837560
Sorry when I mentioned the rpc service I was not looking at exchange which I meant to.  Anyway for some reason that doesn't start automatically now.  I sense I'm heading to a new installation at some point but I agree the domain join issue can't be caused by many things.

Author Comment

ID: 38837660
Running dcdiag the enterprise test says error 1355 global catalog server could not be located.

Accepted Solution

TMS earned 0 total points
ID: 38860077
This problem was as a result of the Sysvol subfolders not mounting during startup.  The NTDFS service did not produce the Do Not Delete folder so the NETLOGIN could not create the subfolders.  I copied over the sysvol folders from the RODC and the server started to report as a Catalogue Server.

Author Closing Comment

ID: 38875431
Reason I accepted my own solution is because I go it working but not fixed.

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Active Directory Audit 18 72
Powershell script update 2 30
active directory 1 40
Exchange 2010:  How to prepare for divoce? 2 41
I've often see, or have been asked, the question about the difference between the Exchange 2010 SP1 version, available as part of Small Business Server (SBS) 2011, and the “normal” Exchange 2010 SP1 Standard. The answer to the question is relativ…
Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now