?
Solved

DNS error 4521

Posted on 2014-04-14
6
Medium Priority
?
1,110 Views
Last Modified: 2014-04-16
I've been getting constant errors on 3 out of my 4 DNS servers in house.  

Error 4521-
"The DNS server encountered error 32 attempting to load zone 60.168.192.in-addr.arpa from Active Directory. The DNS server will attempt to load this zone again on the next timeout cycle. This can be caused by high Active Directory load and may be a transient condition. "

This started when we decommission one of our sites.  We didn't properly decom the DC / DNS server at that site so I ran ntdsutil and followed MS site regarding cleaning up the metadata of a fail demoted DC however I'm not sure how to stop these constant 4521 dns errors.  

Any suggestions where I can find and remove the entry that is constantly trying to load a zone that does not exist anymore?
0
Comment
Question by:jo80ge121
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 25

Expert Comment

by:Zephyr ICT
ID: 39999079
I suspect that zone is the one from the site that was decommissioned?

It might still be loaded from AD/registry...

You could run following command to remove it from AD/registry and delete it (if not deleted already)...

"dnscmd /config <zonename> /bootmethod [0|1|2|3]"

0 is no source, the standard is 3 (AD/registry) ... 2 is registry and 1 is bind/local DNS directory...
0
 
LVL 17

Expert Comment

by:Brad Bouchard
ID: 39999822
Did you load the DNS GUI on each of these servers and make sure to remove that Reverse Lookup Zone?  The zone you're referring to is a Reverse Lookup Zone and needs to be removed manually since you didn't remove the site properly.
0
 

Author Comment

by:jo80ge121
ID: 40000111
spravtek: yes it was the zone from the site that decom.  I will try what you suggested.

BradBouchard: all reverse lookup zones from each DNS has been manually removed.
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 26

Accepted Solution

by:
DrDave242 earned 2000 total points
ID: 40002122
If the above suggestions don't work, you can use ADSI Edit to find and delete the zone from Active Directory:

1.

Run adsiedit.msc at an elevated command prompt on one of your DCs/DNS servers.

2.

Right-click ADSI Edit in the left pane and select Connect to...

3.

In the Connection Settings window, select the radio button labeled Select or type a Distinguished Name or Naming Context.

4.

Since the zone in question is a reverse lookup zone, we'll start by looking in the ForestDnsZones partition. If your AD domain is named domain.com, you'll type DC=ForestDnsZones,DC=domain,DC=com in the input field to connect to that partition. You can optionally type something in the Name field (like ForestDnsZones) to identify the connection, but this isn't required. Click OK to connect to the partition.

5.

In the left pane, expand ForestDNSZones\DC=ForestDnsZones,DC=domain,DC=com\CN=MicrosoftDNS. You should see folders for each DNS zone that's stored in the ForestDnsZones partition (each zone configured to replicate to every DC running DNS in the forest).

6.

If you see the offending zone, delete it. (You'll want to force replication to the other DCs at this point.) If not, go back to step 2, but connect to the DomainDnsZones partition this time.
0
 

Author Comment

by:jo80ge121
ID: 40004650
DrDave242: thank you.  It was exactly what I was hoping for since I've heard other talk about ADSIEDIT being the tool to fix it.  Just going to wait a day to make sure i don't see anymore errors.
0
 

Author Comment

by:jo80ge121
ID: 40005359
DrDave242: no need to wait a day.  For the past month I've been seeing error 4521 almost every couple of minutes now not a peep from the event logger since I applied your suggestion.  I'm confident this solved it.  Thanks again.
0

Featured Post

Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let's recap what we learned from yesterday's Skyport Systems webinar.
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Suggested Courses

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question