Solved

DNS error 4521

Posted on 2014-04-14
6
1,064 Views
Last Modified: 2014-04-16
I've been getting constant errors on 3 out of my 4 DNS servers in house.  

Error 4521-
"The DNS server encountered error 32 attempting to load zone 60.168.192.in-addr.arpa from Active Directory. The DNS server will attempt to load this zone again on the next timeout cycle. This can be caused by high Active Directory load and may be a transient condition. "

This started when we decommission one of our sites.  We didn't properly decom the DC / DNS server at that site so I ran ntdsutil and followed MS site regarding cleaning up the metadata of a fail demoted DC however I'm not sure how to stop these constant 4521 dns errors.  

Any suggestions where I can find and remove the entry that is constantly trying to load a zone that does not exist anymore?
0
Comment
Question by:jo80ge121
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 25

Expert Comment

by:Zephyr ICT
ID: 39999079
I suspect that zone is the one from the site that was decommissioned?

It might still be loaded from AD/registry...

You could run following command to remove it from AD/registry and delete it (if not deleted already)...

"dnscmd /config <zonename> /bootmethod [0|1|2|3]"

0 is no source, the standard is 3 (AD/registry) ... 2 is registry and 1 is bind/local DNS directory...
0
 
LVL 17

Expert Comment

by:Brad Bouchard
ID: 39999822
Did you load the DNS GUI on each of these servers and make sure to remove that Reverse Lookup Zone?  The zone you're referring to is a Reverse Lookup Zone and needs to be removed manually since you didn't remove the site properly.
0
 

Author Comment

by:jo80ge121
ID: 40000111
spravtek: yes it was the zone from the site that decom.  I will try what you suggested.

BradBouchard: all reverse lookup zones from each DNS has been manually removed.
0
Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

 
LVL 26

Accepted Solution

by:
DrDave242 earned 500 total points
ID: 40002122
If the above suggestions don't work, you can use ADSI Edit to find and delete the zone from Active Directory:

1.

Run adsiedit.msc at an elevated command prompt on one of your DCs/DNS servers.

2.

Right-click ADSI Edit in the left pane and select Connect to...

3.

In the Connection Settings window, select the radio button labeled Select or type a Distinguished Name or Naming Context.

4.

Since the zone in question is a reverse lookup zone, we'll start by looking in the ForestDnsZones partition. If your AD domain is named domain.com, you'll type DC=ForestDnsZones,DC=domain,DC=com in the input field to connect to that partition. You can optionally type something in the Name field (like ForestDnsZones) to identify the connection, but this isn't required. Click OK to connect to the partition.

5.

In the left pane, expand ForestDNSZones\DC=ForestDnsZones,DC=domain,DC=com\CN=MicrosoftDNS. You should see folders for each DNS zone that's stored in the ForestDnsZones partition (each zone configured to replicate to every DC running DNS in the forest).

6.

If you see the offending zone, delete it. (You'll want to force replication to the other DCs at this point.) If not, go back to step 2, but connect to the DomainDnsZones partition this time.
0
 

Author Comment

by:jo80ge121
ID: 40004650
DrDave242: thank you.  It was exactly what I was hoping for since I've heard other talk about ADSIEDIT being the tool to fix it.  Just going to wait a day to make sure i don't see anymore errors.
0
 

Author Comment

by:jo80ge121
ID: 40005359
DrDave242: no need to wait a day.  For the past month I've been seeing error 4521 almost every couple of minutes now not a peep from the event logger since I applied your suggestion.  I'm confident this solved it.  Thanks again.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article runs through the process of deploying a single EXE application selectively to a group of user.
In-place Upgrading Dirsync to Azure AD Connect
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question