DNS Delegation Issue

Posted on 2014-11-20
Last Modified: 2014-11-24
I am trying to add servers and it resolves successfully but when i click "apply" it throws this error.  

"Failure to write DNS record <server1.> refused"

Question by:Sean Kelsey
LVL 37

Expert Comment

by:Neil Russell
ID: 40455930
Please explain EXACTLY what it is you are trying to do? What gives the error when you try to do what?

Author Comment

by:Sean Kelsey
ID: 40456130
I am trying to add 2 DC's to DNS delegation but it fails and throws the following error. "Failure to write DNS record <server1.> refused"

Also when I run repadmin /kcc * it says access denied to every DC in the forest. When I run repadmin /syncall etc. replication goes through fine.

Author Comment

by:Sean Kelsey
ID: 40456135
I also ran DCDAIG /TEST:CheckSecurityError and it comes out successful.
LVL 37

Expert Comment

by:Neil Russell
ID: 40456143
Can you post the actual output from the repadmin /kcc please
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.


Author Comment

by:Sean Kelsey
ID: 40456149
In review I found out that it wasnt completely successful. Failed here:
    Replicating Directory Changes In Filtered Set
LVL 10

Expert Comment

by:Walter Padrón
ID: 40456154
Don't fully understand your question but

DC's records doesn't need to be added manually to DNS.
The Netlogon service should register the records, restart the service and wait for 15 min
You can also register records typing     C:\> ipconfig /registerdns

Best regards
LVL 37

Expert Comment

by:Neil Russell
ID: 40456155
Do you intend to have RODC in the domain? That error is not unusual if you have NOT prepped your domain for RODC but if you dont need them then you can ignore that one.
LVL 37

Expert Comment

by:Neil Russell
ID: 40456159
You still have not answer "What EXACTLY" is it your trying to do?
Is it as simple as wpadron thinks? Your just adding two dc's to a domain and not seing the DNS records yet?
LVL 19

Accepted Solution

compdigit44 earned 500 total points
ID: 40460880
I "assume" you have an existing Zone which you are adding additional DNS servers to, in order to service the zone. Is the Zone AD integrated?  If so check to see if the DNSadmins groups has the proper permissions on the zone...

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Group policy backup error 8 25
Change AD password via MS Access DB 2 17
who removed AD Domain ID 9 18
file name warning 4 20
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now