Solved

Fixing DNS on Server 2008 R2 Machine

Posted on 2014-02-07
12
2,184 Views
Last Modified: 2014-02-21
Hi all,

We're trying to fix an ongoing issue with a small network.  The server is Server 2008 R2 - it's a single server setup and its the DC (GC) and running AD, DNS, etc.

I suspect that the DNS issues might be the root cause.  Right now if we go in to DNS and click on the domain zone file we get the error below:

The DNS server encountered a problem while attempting to load the zone.  The zone data may not be available in Active Directory, or the zone data is corrupt.

Correct the problem then either press F5, or on the Action menu, click Refresh

DNS Server Error
Obviously we've tried refreshing, restarting, etc. but no luck.  Active Directory seems to be working fine and the network is full operational despite these problem but we know it's only a matter of time.

Any ideas would be much appreciated.

Thanks

Bob
0
Comment
Question by:Mango-Man
  • 6
  • 5
12 Comments
 
LVL 9

Assisted Solution

by:stu29
stu29 earned 500 total points
Comment Utility
1. Ensure the server is pointed to itself as the DNS server
2. Try loading the DNS snap in on another computer to ensure it is not a snapin issue.
2. Run DCDiag /test:dns .. fix any issues

Let us know what happens after this?
0
 
LVL 1

Author Comment

by:Mango-Man
Comment Utility
Thanks for your help!

1) Server is pointing to itself for DNS
2) Snap in from other PC gives same error
3) DCDIAG/test:dns shows the information below.  DNS test is failing (presumably because of the error above):

   Testing server: Default-First-Site-Name\SERVERLUS
      Starting test: Connectivity
         ......................... SERVERLUS passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SERVERLUS

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         ......................... SERVERLUS failed test DNS

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : MAGIC

   Running enterprise tests on : MAGICALES.COM
      Starting test: DNS
         Test results for domain controllers:

            DC: SERVERLUS.MAGICALES.COM
            Domain: MAGICALES.COM


               TEST: Basic (Basc)
                  Warning: adapter
                  [00000007] Intel(R) 82579LM Gigabit Network Connection has
                  invalid DNS server: 192.168.8.10 (SERVERLUS)
                  Error: all DNS servers are invalid
                  Warning: no DNS RPC connectivity (error or non Microsoft DNS s
erver is running)

         Summary of test results for DNS servers used by the above domain
         controllers:

            DNS server: 192.168.8.10 (SERVERLUS)
               1 test failure on this DNS server
               Name resolution is not functional. _ldap._tcp.MAGICALES.COM.
failed on the DNS server 192.168.8.10

         Summary of DNS test results:

                                            Auth Basc Forw Del  Dyn  RReg Ext
            _________________________________________________________________
            Domain: MAGICALES.COM
               SERVERLUS                       PASS FAIL n/a  n/a  n/a  n/a  n/a

         ......................... MAGICALES.COM failed test DNS

Open in new window

0
 
LVL 9

Assisted Solution

by:stu29
stu29 earned 500 total points
Comment Utility
Try running it with the /v switch to see the verbose output.
0
 
LVL 1

Author Comment

by:Mango-Man
Comment Utility
Thanks for the tip, there's more information but with my limited knowledge I'm not any more enlightened!:

Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\Windows\system32>DCDIAG/test:dns /v

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   * Verifying that the local machine SERVERLUS, is a Directory Server.
   Home Server = SERVERLUS
   * Connecting to directory service on server SERVERLUS.
   * Identified AD Forest.
   Collecting AD specific global data
   * Collecting site info.
   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=MAGICALES,
DC=COM,LDAP_SCOPE_SUBTREE,(objectCategory=ntDSSiteSettings),.......
   The previous call succeeded
   Iterating through the sites
   Looking at base site object: CN=NTDS Site Settings,CN=Default-First-Site-Name
,CN=Sites,CN=Configuration,DC=MAGICALES,DC=COM
   Getting ISTG and options for the site
   * Identifying all servers.
   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=MAGICALES,
DC=COM,LDAP_SCOPE_SUBTREE,(objectClass=ntDSDsa),.......
   The previous call succeeded....
   The previous call succeeded
   Iterating through the list of servers
   Getting information for the server CN=NTDS Settings,CN=SERVERLUS,CN=Servers,CN=D
efault-First-Site-Name,CN=Sites,CN=Configuration,DC=MAGICALES,DC=COM
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   * Identifying all NC cross-refs.
   * Found 1 DC(s). Testing 1 of them.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SERVERLUS
      Starting test: Connectivity
         * Active Directory LDAP Services Check
         Determining IP4 connectivity
         * Active Directory RPC Services Check
         ......................... SERVERLUS passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SERVERLUS
      Test omitted by user request: Advertising
      Test omitted by user request: CheckSecurityError
      Test omitted by user request: CutoffServers
      Test omitted by user request: FrsEvent
      Test omitted by user request: DFSREvent
      Test omitted by user request: SysVolCheck
      Test omitted by user request: KccEvent
      Test omitted by user request: KnowsOfRoleHolders
      Test omitted by user request: MachineAccount
      Test omitted by user request: NCSecDesc
      Test omitted by user request: NetLogons
      Test omitted by user request: ObjectsReplicated
      Test omitted by user request: OutboundSecureChannels
      Test omitted by user request: Replications
      Test omitted by user request: RidManager
      Test omitted by user request: Services
      Test omitted by user request: SystemLog
      Test omitted by user request: Topology
      Test omitted by user request: VerifyEnterpriseReferences
      Test omitted by user request: VerifyReferences
      Test omitted by user request: VerifyReplicas

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         See DNS test in enterprise tests section for results
         ......................... SERVERLUS passed test DNS

   Running partition tests on : ForestDnsZones
      Test omitted by user request: CheckSDRefDom
      Test omitted by user request: CrossRefValidation

   Running partition tests on : DomainDnsZones
      Test omitted by user request: CheckSDRefDom
      Test omitted by user request: CrossRefValidation

   Running partition tests on : Schema
      Test omitted by user request: CheckSDRefDom
      Test omitted by user request: CrossRefValidation

   Running partition tests on : Configuration
      Test omitted by user request: CheckSDRefDom
      Test omitted by user request: CrossRefValidation

   Running partition tests on : MAGICALES
      Test omitted by user request: CheckSDRefDom
      Test omitted by user request: CrossRefValidation

   Running enterprise tests on : MAGICALES.COM
      Starting test: DNS
         Test results for domain controllers:

            DC: SERVERLUS.MAGICALES.COM
            Domain: MAGICALES.COM


               TEST: Authentication (Auth)
                  Authentication test: Successfully completed

               TEST: Basic (Basc)
                  The OS
                  Microsoft Windows Server 2008 R2 Foundation  (Service Pack lev
el: 1.0)
                  is supported.
                  NETLOGON service is running
                  kdc service is running
                  DNSCACHE service is running
                  DNS service is running
                  DC is a DNS server
                  Network adapters information:
                  Adapter
                  [00000007] Intel(R) 82579LM Gigabit Network Connection:
                     MAC address is 00:25:90:25:A8:05
                     IP Address is static
                     IP address: 192.168.8.10
                     DNS servers:
                        Warning:
                        127.0.0.1 (SERVERLUS) [Invalid]
                        Warning: adapter
                        [00000007] Intel(R) 82579LM Gigabit Network Connection
                        has invalid DNS server: 127.0.0.1 (SERVERLUS)
                  Error: all DNS servers are invalid
                  The A host record(s) for this DC was found
                  The SOA record for the Active Directory zone was found
                  The Active Directory zone on this DC/DNS server was found prim
ary
                  Root zone on this DC/DNS server was not found

               TEST: Forwarders/Root hints (Forw)
                  Recursion is enabled
                  Forwarders Information:
                     208.67.220.220 (<name unavailable>) [Valid]
                     208.67.222.222 (<name unavailable>) [Valid]

               TEST: Delegations (Del)
                  No delegations were found in this zone on this DNS server

               TEST: Dynamic update (Dyn)
                  Warning: Failed to add the test record dcdiag-test-record in z
one MAGICALES.COM
                  [Error details: 9004 (Type: Win32 - Description: DNS request n
ot supported by name server.)]
                  Test record dcdiag-test-record deleted successfully in zone BV
IYACHTSALES.COM

            TEST: Records registration (RReg)
               Error: Record registrations cannot be found for all the network
               adapters

         Summary of test results for DNS servers used by the above domain
         controllers:

            DNS server: 192.168.8.10 (SERVERLUS)
               1 test failure on this DNS server
               Name resolution is not functional. _ldap._tcp.MAGICALES.COM.
failed on the DNS server 192.168.8.10
               [Error details: 9501 (Type: Win32 - Description: No records found
 for given DNS query.)]

            DNS server: 208.67.220.220 (<name unavailable>)
               All tests passed on this DNS server

            DNS server: 208.67.222.222 (<name unavailable>)
               All tests passed on this DNS server

         Summary of DNS test results:

                                            Auth Basc Forw Del  Dyn  RReg Ext
            _________________________________________________________________
            Domain: MAGICALES.COM
               SERVERLUS                       PASS FAIL PASS PASS WARN FAIL n/a

         ......................... MAGICALES.COM failed test DNS
      Test omitted by user request: LocatorCheck
      Test omitted by user request: Intersite

C:\Windows\system32>

Open in new window

0
 
LVL 9

Assisted Solution

by:stu29
stu29 earned 500 total points
Comment Utility
Looks like it does not like you using the loopback IP address for the DNS server on the NIC.  Try changing it to the actual IP address of the server.  Restart DNS

Re-run your test.
0
 
LVL 10

Expert Comment

by:Pramod Ubhe
Comment Utility
Also check if there are any errors related to AD in event logs specifically related to replication or FRS.
0
Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

 
LVL 1

Author Comment

by:Mango-Man
Comment Utility
Stu29 - We get the same error with the loopback address or the internal IP I'm afraid - it just happens that the test above was when the loopback address was used.

Pramod_ubhe - Lots of errors relating to AD (as DNS is broken) but nothing specifically to do with replication or FRS
0
 
LVL 9

Assisted Solution

by:stu29
stu29 earned 500 total points
Comment Utility
Before we go digging deeper .. try running DCDIAG /fix ... this will correct some minor issues and maybe we will get lucky.  restart DNS

If this doe not work .. can you show us

IP settings on the DNS server
Right click on the failed Zone and show us general, SOA and Name servers tabs?
0
 
LVL 9

Assisted Solution

by:stu29
stu29 earned 500 total points
Comment Utility
I just looked at your image again .... do you have a reverse lookup zone for your subnets?
0
 
LVL 1

Author Comment

by:Mango-Man
Comment Utility
Hey Stu29,

Sorry for the delay - been in transit for a while but back on land now.

I checked and we have no PRT records setup and any attempts to create them result in an error:

The zone cannot be created.  The was a server failure.

I ran DCDIAG /fix and whizzed through a ton of stuff but didn't seem to fix anything unfortunately.

I think we're going to have to consider the possibility of a server reinstall.  :-(

Thanks for your help!
0
 
LVL 9

Accepted Solution

by:
stu29 earned 500 total points
Comment Utility
Mango-man,

I have never seen DNS broken to the point you would have to re-install the server.

1. Try to uninstall and re-install DNS

OR

2. Bring up a second DNS server, then point your DC to that as the DNS server.  Once that is working correctly, do the above step.

Make sure you have a good backup first and choose and path to follow.  You should not have to rebuild your domain.
0
 
LVL 1

Author Comment

by:Mango-Man
Comment Utility
Hi Stu29,

Ok thanks for that - I was worried that AD was so closely tied to DNS that uninstalling DNS would break AD beyond repair.

We'll make a plan to try that thanks!

Bob
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

This article will review the basic installation and configuration for Windows Software Update Services (WSUS) in a Windows 2012 R2 environment.  WSUS is a Microsoft tool that allows administrators to manage and control updates to be approved and ins…
I don't know if many of you have made the great mistake of using the Cisco Thin Client model with the management software VXC. If you have then you are probably more then familiar with the incredibly clunky interface, the numerous work arounds, and …
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now